retention policy v1

Exactly where the message exists.

PlugMail separates the active delivery copy, your durable local copy, and a short-lived encrypted recovery copy. “Deleted” means logically and cryptographically inaccessible through the service; we do not market fictional per-file SSD overwrites.

The custody handoff

Deletion follows proof, not a timer guess.

verifiable
  1. 01
    receive

    PlugMail accepts the full message into the temporary delivery queue.

  2. 02
    commit

    The primary device verifies the MIME hash and commits it into the encrypted local vault.

  3. 03
    acknowledge

    The device signs a nonce-bound local-commit acknowledgement.

  4. 04
    purge

    The active server copy is removed; an encrypted recovery copy expires within 72 hours.

local 94server 2recovery 4

Free

100 live messages
  • Maximum 100 unsynchronized server messages.
  • Unsynchronized messages are not silently deleted after 72 hours.
  • Active copy leaves after verified local commit.
  • Encrypted recovery copy expires no later than 72 hours after acknowledgement.
  • Local storage is bounded by your device.

Premium

choice
  • Pull & Purge remains available.
  • Optional persistent private cloud vault, encrypted for the user.
  • “Unlimited” means no fixed mailbox-message quota, subject to fair use and platform capacity.
  • Persistent mode is opt-in and visibly different from Pull & Purge.
Loss model: after the 72-hour recovery copy expires, PlugMail cannot recover a message that was deleted from every registered local backup. The client must make this visible before activation.